Insights permissions are simple by design—users either have access or they don’t.
There are no granular, report-level permissions. Instead, access is controlled through a small set of firm permissions that determine what users can see and do in Insights.
Required Plan, License, and Permissions
To use Insights, users must be granted Access to Insights.
Additional permissions determine whether they can create, share, or build reports using admin-level data.
Why this matters
Understanding how Insights permissions work helps firms:
Safely share reports without overcomplicating access controls
Know when sensitive data (like salary information) may be visible
Assign the right permissions to the right team members—without surprises
Table of Contents
How Insights Access Works
Insights does not support role-based or object-level permissions.
Users either have access to Insights or they do not
There are no restrictions by report, dashboard, or dataset once access is granted
The only Insights-specific permissions you can control are:
Access to Insights
Ability to Create/Share Answers
Creating and Sharing Answers
Users with the Ability to Create/Share Answers permission can:
Build new Answers (reports)
Share Answers with other users who have access to Insights
Users without this permission can still:
View Answers that have been shared with them
Interact with report data (filter, explore, download, etc.)
Admin-Level Access and Admin Data Sources
Only admin-level users can create reports using Admin Data Sources in Insights.
However, “admin-level” in Insights does not mean the user must be a Canopy Admin.
A user is considered admin-level for Insights if they have this permission:
Team Member Salary | View and edit team member salary and hourly rate
With this permission:
The user can access Admin Data Sources in Insights
This applies even if they are not an Admin in Canopy
Salary Data Visibility
Important to know:
Any report built using an Admin Data Source includes salary information
If that report is shared with a non-admin user:
The report is fully viewable
Salary data is not masked or restricted
This applies regardless of the user’s other Canopy permissions
Best practice:
Users with access to Admin Data Sources should be intentional about who they share reports with, since salary data is always fully visible to report viewers.
Canned Dashboards and Admin Data
Most pre-built (canned) Canopy dashboards:
Do not use Admin Data Sources
Are visible to all users with access to Insights
If a canned dashboard does use an Admin Data Source:
It is only visible to admin-level users (as defined above)
Summary
Insights permissions are intentionally simple—no granular controls
Users either have access to Insights or they don’t
Only two permissions apply:
Access to Insights
Ability to Create/Share Answers
Admin Data Sources are tied to salary permissions, not Canopy admin status
Any shared report built on Admin Data Sources exposes all included data
Need help?
Need help deciding who should have admin-level access in Insights?
Contact Support or ask Penny, our AI support bot, for guidance.
